CVE Database /
CVE-2024-6455
CVE · Medium
CVE-2024-6455 — ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor [elementskit-lite] < 3.2.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-6455
|
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor [elementskit-lite] < 3.2.1 |
Exposure of Sensitive Information to an Unauthorized Actor |
Medium
5.3
|
< 3.2.1
|
3.2.1 |
2024-07-18 |
—
|
CVE-2024-6455
The ElementsKit Elementor addons plugin for WordPress contains an oversight that allows unauthorized access to sensitive content. In versions 3.2.0 and earlier, the ekit_widgetarea_content function lacks necessary permission checks, enabling unauthenticated users to view any item created with Elementor, including unpublished drafts and private content.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings